US2025219836A1PendingUtilityA1

Apparatus and method for password-based distributed authentication

Assignee: ELECTRONICS & TELECOMMUNICATIONS RES INSTPriority: Dec 27, 2023Filed: Aug 9, 2024Published: Jul 3, 2025
Est. expiryDec 27, 2043(~17.4 yrs left)· nominal 20-yr term from priority
H04L 2209/46H04L 9/085H04L 9/0863H04L 9/3213H04L 9/3226
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Disclosed herein is an apparatus and method for password-based distributed authentication. The apparatus includes memory in which at least one program is recorded and a processor for executing the program. The program may perform at least one of registering a password input by a user in a service membership sign-up procedure in multiple servers in a distributed manner based on multi-party computation, authenticating a password input by the user in a login procedure based on multi-party computation with the multiple servers, or acquiring resources of a service requested by the authenticated user, or a combination thereof.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An apparatus for password-based distributed authentication, comprising:
 memory in which at least one program is recorded; and   a processor for executing the program,   wherein the program performs at least one of   registering a password input by a user in a service membership sign-up procedure in multiple servers in a distributed manner based on multi-party computation,   authenticating a password input by the user in a login procedure based on multi-party computation with the multiple servers, or   acquiring a resource of a service requested by the authenticated user, or   a combination thereof.   
     
     
         2 . The apparatus of  claim 1 , wherein, when registering the password, the program performs
 receiving an identifier and the password from the user who requests signing up for a membership,   converting the received password into a password verification value,   generating a secret-sharing polynomial using the password verification value,   generating multiple password verification fragment values using the secret-sharing polynomial and IDs of the multiple servers, and   distributing the password verification fragment values to corresponding ones of the multiple servers.   
     
     
         3 . The apparatus of  claim 2 , wherein converting the received password comprises converting the received password into the password verification value using a salt or a hash. 
     
     
         4 . The apparatus of  claim 2 , wherein generating the secret-sharing polynomial comprises generating the secret-sharing polynomial using a Shamir's secret sharing method. 
     
     
         5 . The apparatus of  claim 1 , wherein, when authenticating the password, the program performs
 generating a token generation key when an identifier and the password are input by the user,   converting the password input by the user into a password verification value,   restoring a password verification comparison value,   checking whether the restored password verification comparison value matches the password verification value,   generating a token key and a token based on the token generation key when the password verification comparison value matches the password verification value, and   storing the generated token.   
     
     
         6 . The apparatus of  claim 5 , wherein
 when restoring the password verification comparison value, the program restores the password verification comparison value based on password verification fragment values of t servers, among N servers across which the password verification fragment values are distributed, and   the password verification comparison value is calculated as a sum of Lagrange basis polynomials multiplied by the respective password verification fragment values.   
     
     
         7 . The apparatus of  claim 5 , wherein the token includes a token signature and token data. 
     
     
         8 . The apparatus of  claim 7 , wherein the token data includes at least one of a user ID, a token serial number, service access authority information, a token issuance date and time, or a token expiration date and time, or a combination thereof. 
     
     
         9 . The apparatus of  claim 5 , wherein the token key is generated based on a sum of token generation keys initially generated by a user terminal and t servers. 
     
     
         10 . The apparatus of  claim 1 , wherein, when acquiring the resource, the program performs
 retrieving whether a token for the requested service is present,   transferring the retrieved token to a server providing the requested service, and   receiving the resource from the server when the token is verified.   
     
     
         11 . An apparatus for password-based distributed authentication, comprising:
 memory in which at least one program is recorded; and   a processor for executing the program,   wherein the program performs at least one of   registering password verification fragment values generated through multi-party computation with one or more additional servers based on a password input by a user through a user terminal in a service membership sign-up procedure,   authenticating a password input by the user in a login procedure based on multi-party computation using the password verification fragment values registered in the one or more additional servers in a distributed manner, or   providing a resource of a service requested from the user terminal based on token verification, or   a combination thereof.   
     
     
         12 . The apparatus of  claim 11 , wherein, when authenticating the password, the program performs
 reading the password verification fragment values corresponding to an identifier of the user and generating a token generation key,   converting the password input by the user into a password verification value,   restoring a password verification comparison value from the password verification fragment values registered in a distributed manner through multi-party computation with the one or more additional servers,   checking whether the restored password verification comparison value matches the password verification value,   generating a token key and a token based on the token generation key when the password verification comparison value matches the password verification value, and   storing the generated token key.   
     
     
         13 . The apparatus of  claim 12 , wherein the token key is generated based on a sum of token generation keys initially generated by the user terminal and t servers. 
     
     
         14 . The apparatus of  claim 11 , wherein, when providing the resource, the program performs
 receiving a service request and a token from the user terminal,   retrieving a token key corresponding to the token,   verifying the token using the retrieved token key, and   providing the resource when the token is verified.   
     
     
         15 . The apparatus of  claim 14 , wherein, when verifying the token, the program performs
 generating a token signature using the retrieved token key and token data included in the token, and   checking whether the generated token signature matches a token signature included in the token.   
     
     
         16 . A method for password-based distributed authentication, comprising:
 receiving an identifier and a password from a user who requests signing up for a membership;   converting the received password into a password verification value;   generating a secret-sharing polynomial using the password verification value;   generating multiple password verification fragment values using the secret-sharing polynomial and IDs of multiple servers; and   distributing the password verification fragment values to corresponding ones of the multiple servers.   
     
     
         17 . The method of  claim 16 , further comprising:
 generating a token generation key when an identifier and a password are input by the user;   converting the password input by the user into a password verification value;   restoring a password verification comparison value;   checking whether the restored password verification comparison value matches the password verification value;   generating a token key and a token based on the token generation key when the password verification comparison value matches the password verification value; and   storing the generated token.   
     
     
         18 . The method of  claim 17 , wherein
 restoring the password verification comparison value comprises restoring the password verification comparison value based on password verification fragment values of t servers, among N servers across which the password verification fragment values are distributed, and   the password verification comparison value is calculated as a sum of Lagrange basis polynomials multiplied by the respective password verification fragment values.   
     
     
         19 . The method of  claim 18 , wherein the token key is generated based on a sum of token generation keys initially generated by a user terminal and the t servers. 
     
     
         20 . The method of  claim 16 , further comprising:
 acquiring a resource of a service requested by the user,   wherein:   acquiring the resource includes   retrieving whether a token for the requested service is present,   transferring the retrieved token to a server providing the requested service, and   receiving the resource from the server when the token is verified, and   the token includes a token signature and token data and is verified depending on whether the token signature included in the transferred token matches a token signature generated by the server using a token key and the token data.

Join the waitlist — get patent alerts

Track US2025219836A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.